What is the NCSC-FI CNA?
NCSC-FI is a CVE Numbering Authority (CNA) — an organization authorized to assign CVE IDs to vulnerabilities in its scope. It has published 10 CVE records since 2024.
How many CVEs has NCSC-FI published?
NCSC-FI has published 10 CVE records, including 10 in the last two years.
What is NCSC-FI's CVE data quality grade?
RadicalNotion.AI grades NCSC-FI's CVE data quality as A, with an overall completeness score of 100%. This reflects how consistently its CVE records include vendor (100%), product (100%), CVSS (100%), and CWE (100%) information.
What products does NCSC-FI publish CVEs for?
NCSC-FI most frequently publishes CVEs for Valmet DNA, lapswebui, Pro Cloud Server, Sparx Pro Cloud Server, Sparx Enterprise Architect.
Which vendors does NCSC-FI cover?
NCSC-FI publishes CVEs across 6 distinct vendors, most often Sparx Systems Pty Ltd., Valmet, Sparx Systems, truesec, danofficeit.
Is NCSC-FI actively publishing CVEs?
NCSC-FI is currently active, based on 10 CVEs in the last two years.
What is the average severity of NCSC-FI's CVEs?
The average CVSS base score across NCSC-FI's scored CVEs is 7.5.
How many critical CVEs has NCSC-FI published?
NCSC-FI has published 4 critical-severity CVEs and 9 high-severity CVEs.
Are any of NCSC-FI's CVEs in CISA's Known Exploited Vulnerabilities catalog?
No. None of NCSC-FI's CVEs are currently listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.
What are the most common weakness types in NCSC-FI's CVEs?
NCSC-FI's CVEs most often map to these CWE weakness types: CWE-22 (Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')), CWE-613 (Insufficient Session Expiration), CWE-522 (Insufficiently Protected Credentials), CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor).
How does NCSC-FI rank among CNAs?
By total CVE volume, NCSC-FI ranks #305 of 370 CNAs, and it reports more complete CVE records than 60% of all CNAs.